peter bassill · operator
$ cve CVE-2018-16618 JSON

CVE-2018-16618

9.8
CRITICAL · CVSS 3.0 · EPSS 8% (pctl 95)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS8.03% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2019-06-19
Last modified2026-06-17

Affected (9)

VendorProduct
vtech80-183803
vtech80-183804
vtech80-183805
vtech80-183807
vtech80-183822
vtech80-183823
vtech80-183824
vtech80-1838xx
vtechstorio max firmware

References

→ the Explorer  ·  watch your stack  ·  NVD